Request a device + user code (RFC 8628 §3.2)

Initiates a device-authorization grant. The CLI calls this first and receives a short user_code to display plus an opaque device_code to poll /api/auth/cli/token with (issue #165). Accepts both application/x-www-form-urlencoded (RFC 8628 §3.2, preferred) and application/json — the server normalizes form-urlencoded bodies to JSON before Better Auth's deviceAuthorization() plugin sees them. Clients are gated by validateClient — only OAuth clients registered with the device-code grant are accepted.

POST/api/auth/device/code

Request Body

curl -X POST "https://your-instance/api/auth/device/code" \  -H "Content-Type: application/json" \  -d '{    "client_id": "string"  }'
{
  "device_code": "string",
  "user_code": "string",
  "verification_uri": "http://example.com",
  "verification_uri_complete": "http://example.com",
  "expires_in": 0,
  "interval": 0
}
{
  "error": "invalid_client",
  "error_description": "string"
}